Privacy Policy
Updated: 21 July 2026
How Bassario collects, uses, stores, shares and deletes the data of website and app users.
1. Scope of this policy
This Policy describes what information Bassario receives about users of the website, the mobile apps and related services, why it is used, who it may be shared with, how it is protected and what rights the user has. The Policy applies together with the User Agreement, the Terms of Use, the Listing Rules and other Bassario documents.
2. Who processes the data
The operator of the Bassario service is Bassario, an individual entrepreneur registered in Georgia, the owner of the bassario.com domain and of the Bassario mobile apps. A single address is used for enquiries about personal data, accounts, listings, complaints and legal matters: support@bassario.com.
3. Data we collect
The data collected depends on which functions the user uses: browsing listings, signing in with Google or Apple, publishing a listing, chat, favourites, the map or contacting support. For account security and session management we also record technical session data when signing in: a random device identifier (not a hardware one), information about the browser or app (User-Agent) and a truncated IP address. This data is tied to the session, is available to the user in the «Devices and sessions» section and is stored until the session ends or expires.
- account data: name, email, avatar, Google or Apple account identifier and technical sign-in attributes;
- listing data: description, category, price, currency, address or district, coordinates of the item, characteristics, photos and moderation status;
- communication data: chat messages, time of sending, conversation participants, attachments (photos, videos, audio recordings, voice messages and files), quoted messages in replies, and complaints about correspondence
- user activity data: favourites, views, search queries, filters, the selected map area, interaction with listings;
- technical data: IP address, date and time of the request, user agent, device type, browser, language, application errors, session identifiers;
- support data: email, the content of the request, attached files, the history of communication and the outcome of the review.
- phone verification data: phone number, country or country code, verification status, the time the SMS code was sent and checked;
- technical message status marks: sent, delivered, read, and for voice and audio messages also played; such marks are visible to the other party to the correspondence
- support request data: the content of the request, the history of correspondence with the agent, the status and the service quality rating
- push notification tokens and device information necessary to deliver notifications about new messages
4. Data published by users
Listings, photos, the seller's name, the district or address of the item, the price and part of the profile information may be visible to other users, search engines and link preview services. A user must not publish third parties' personal data without a lawful basis or the consent of those persons.
5. How we use data
Bassario processes data only for purposes related to the operation of the marketplace, security, performance of the user documents and user support.
- creating an account, signing in with Google and maintaining the session;
- publishing, searching, displaying and promoting listings;
- operation of the map, listing cards, photo galleries, favourites and chat;
- moderation of listings, messages, photos and accounts;
- prevention of fraud, spam, duplicates, unlawful content and circumvention of blocks;
- responding to enquiries, handling complaints and disputes between users;
- technical diagnostics, protection of the infrastructure and improvement of service quality;
- compliance with legal requirements and requests from competent authorities, and protection of the rights of Bassario and its users.
- verification of a phone number to protect the account and to counter spam, fraud and abuse;
6. Legal bases for processing
Depending on the situation, data is processed on the basis of the acceptance of the user documents, the necessity of providing the service functions, the user's consent, Bassario's legitimate interest in the security and development of the service, and the obligation to comply with applicable law. If separate consent is required for a particular function, Bassario will request it before such processing begins.
7. Google and Apple Sign-In, third-party services
When signing in with Google or Apple, Bassario receives from the respective provider the data necessary to identify the user: the account identifier, and also the email, name and avatar if the user has allowed them to be shared. Bassario does not receive the password of the Google or Apple account. Apple allows the real email to be hidden and a relay address to be passed to the service — Bassario treats it in the same way as an ordinary email. Yandex.Maps services are used to display maps and to determine an address from coordinates: the map provider may receive technical data necessary for the operation of the map and geocoding. Push notifications are delivered through Firebase Cloud Messaging (Google): a technical device token and the notification text are passed to it. Infrastructure providers process data as Bassario's technical contractors on the Operator's instructions.
8. Who data may be shared with
Bassario does not sell personal data. Data may be shared only to the extent necessary for the operation of the service, security, support and compliance with the law.
- with users of the service — the public part of a listing and the data needed to make contact about the listing;
- with Google — as part of signing in with Google and verifying the token;
- with Apple — as part of signing in with Apple and verifying the identity token;
- with Google (Firebase Cloud Messaging) — the technical device token and the content of the notification, in order to deliver push messages;
- with Yandex.Maps — to display items and the map;
- with providers of hosting, image storage, the database, monitoring and site delivery;
- with moderators and support staff who need access to perform their task;
- with public authorities or a court — only where this is required by applicable law.
- with technical SMS verification providers — the phone number and the necessary technical data, solely to deliver SMS codes and operate the verification function;
9. International transfers
The service uses infrastructure and contractors that may be located in different countries. The main computing capacity, the database and the object storage holding listing photos and correspondence attachments are hosted at a provider's site in the European Union (Germany). Individual contractors — the Google and Apple sign-in providers, the push notification service and the mapping service — may process data outside the EU, including in the United States. Transfers take place to the extent necessary to provide the relevant technical service; contractors act on the Operator's instructions and may not use the data received for their own purposes. Where data is transferred to countries that do not provide a comparable level of protection, the Operator relies on the mechanisms provided for by applicable law (including standard contractual clauses) and applies reasonable organisational and technical safeguards.
10. Data retention
Data is stored for as long as necessary for the operation of the service, security, dispute resolution, performance of the user documents and legal requirements. As a rule, the following periods apply:
- account data — while the account exists; after the account is deleted it is, as a rule, deleted or anonymised within 30 days;
- listings — for the period of publication and subsequent storage in the user's archive; deleted listings — as a rule, up to 90 days;
- correspondence and attachments — while the correspondence exists; after a participant's account is deleted — as a rule, up to 90 days, unless a dispute or an investigation requires longer retention;
- support requests and complaint materials — as a rule, up to 24 months from the closure of the request;
- technical and security logs — as a rule, up to 12 months;
- phone verification data — as a rule, up to 12 months from the date of verification;
- data that the Operator is required to retain by law or that is needed to protect rights in a dispute — for the period established by law or the limitation period.
11. Photos and images
User photos are stored in their original form and as smaller technical copies needed to display previews, cards and galleries quickly. Bassario may use technical image deduplication: if the same file has already been processed, the service may refer to the existing copies instead of uploading and processing it again.
12. Media files in correspondence
A user may attach photos, videos, audio recordings, voice messages and arbitrary files to messages. Such attachments are placed in the Operator's object storage and are available solely to the participants in the relevant correspondence via an authorised link; no public access to attachments is provided. The file name, its type and size, and for media files also the duration and frame dimensions, are processed as technical information necessary for correct display. The Operator applies technical deduplication: a cryptographic checksum of the content is calculated for each file, and if a previously uploaded file is sent again the service refers to the already stored object instead of uploading it again. The checksum is used solely to eliminate duplication and is not used to analyse the content of files.
- photos may be downscaled on the user's device before sending in order to save traffic
- attachments are stored while the correspondence exists and are deleted or anonymised together with it in the manner described in the data retention section
- saving a received attachment to a device is done by the user themselves; any further handling of such a file is outside the Operator's control
13. Access to device features
The mobile app requests access to individual device features solely at the moment the user initiates the corresponding action themselves. Access is granted by the user and may be revoked at any time in the operating system settings; revoking access makes only the related function unavailable and does not affect the rest of the service.
- microphone — only while a voice message is being recorded; recording starts when the corresponding button is held down and stops when it is released; no background recording takes place
- camera and photo gallery — to select or take photos and videos attached to a listing or a message
- file storage — to select a file to send and to save a received attachment at the user's command
- location — to show listings near the selected map area
- notifications — to deliver push messages about new chat messages and significant account events
14. Cookies and similar technologies
The website uses necessary cookies and similar technologies for signing in, security, maintaining the session and basic interface settings. Further details are set out in the Cookie Policy. If Bassario introduces analytics, advertising or marketing cookies, information about them will be added before their use begins.
15. Security
Bassario applies technical and organisational protection measures: HTTPS, access segregation, storage of secrets outside public code, security logs, backups and restriction of access by employees and contractors on a need-to-know basis. That said, no internet service can guarantee absolute protection, so users should take care of their account and devices. If a security incident occurs that may create a risk to users' rights, the Operator will notify the affected users within a reasonable period and, where required by applicable law, the competent supervisory authority, describing the nature of the incident, its likely consequences and the measures taken.
16. Staff access to correspondence
Users' correspondence is not public. Access to the content of correspondence is granted to authorised employees of the Operator strictly on a need-to-know basis and only in the following cases: handling a complaint from one of the participants in the correspondence; checking indications of fraud, breaches of the service rules or threats to user security; a user's request to the support service, where reviewing the correspondence is required to handle it; compliance with a mandatory requirement of an authorised body. Employees' actions with user data are recorded in internal logs. The Operator does not use the content of correspondence for advertising purposes and does not share it with third parties, except in the cases expressly provided for by this Policy.
- a support request is handled in a separate conversation with an agent; the support agent has access only to the correspondence relating to that request
- a service quality rating left by the user is processed as internal information about the work of the support service
17. Automated processing and decisions
Some checks in the service are performed automatically: detection of duplicate listings, prohibited language, indications of spam and fraud, and technical format violations. An automated check may result in a listing not being published immediately, being hidden pending manual review, or individual account functions being temporarily restricted.
- decisions that significantly affect the user (refusal to publish, restriction of functions, blocking of an account) are not taken solely automatically: the user may request that they be reviewed by a person;
- the user may state their position and challenge a decision by contacting support@bassario.com; the procedure is described in the Moderation Policy;
- the Operator does not use automated processing for profiling for advertising purposes and does not take decisions on access to third-party services on that basis.
18. User rights
In relation to their personal data, the user has the rights provided for by applicable data protection law. Requests are sent to support@bassario.com; the Operator responds within the period established by applicable law and may ask the user to confirm ownership of the account so that data is not disclosed to an outsider.
- obtain confirmation of processing and a copy of their data (right of access);
- correct inaccurate data or complete incomplete data;
- delete their data and account — in the manner described on the Account and data deletion page;
- restrict processing or object to processing based on the Operator's legitimate interest;
- receive their data in a structured, machine-readable format and, where technically feasible, have it transmitted to another controller (data portability);
- withdraw consent where processing is based on consent; withdrawal does not affect the lawfulness of processing before it was received;
- lodge a complaint with the competent data protection supervisory authority at their place of residence, work or of the alleged infringement.
19. Account and data deletion
An account can be deleted through the app, the website or by a request to support@bassario.com. The detailed procedure is described on the Account and data deletion page. Before deletion, Bassario may ask the user to confirm ownership of the account in order to protect them from unauthorised deletion.
20. Children and age restrictions
Bassario is intended for users over 18 years of age. The service does not knowingly collect children's data. If it becomes known that a minor has provided data or created an account, please write to support@bassario.com — Bassario will take steps to delete such data.
21. Changes to the policy
Bassario may update the Policy. The date of the last update is stated at the top of the page. In the event of material changes, Bassario may notify users through the website, the app or by email. Continued use of the service after the changes take effect means using the service under the updated rules.
22. Contacts
For questions about personal data, account deletion, security, moderation and legal documents, please write to support@bassario.com.
